借助 Cloudflare Zero Trust 和 Yubico 实现对网络钓鱼的无缝防御的关键(硬件密钥)
2022-09-29
宣布与 Yubico 开展新的合作,为任何规模的企业部署硬件密钥消除障碍...
\n \n
如今,Yubico 安全密钥可供所有 Cloudflare 客户使用,并且可与 Cloudflare 的 Zero Trust 服务轻松整合。此项服务向任何规模的企业开放,从保护家庭网络的家庭到地球上规模最大的雇主。如今,任何 Cloudflare 客户登录 Cloudflare Dashboard,即可以每个密钥低至 10 美元的价格订购硬件安全密钥。
2022 年 7 月,Cloudflare 成功阻止了一起信息泄露事件(由针对 130 多家公司的短信网络钓鱼攻击引起),这归因于该公司配合使用了 Cloudflare Zero Trust 与硬件安全密钥 YubiKey。同时,此次与 YubiKey 制造商 Yubico 开展新的合作,也为任何规模的企业部署硬件密钥消除了障碍。
\n企业需要确保只有合适的用户才能连接到其敏感资源——无论是自我托管的网络应用程序、SaaS 工具,还是依赖任意 TCP 连接和 UDP 流传输的服务。用户传统上通过用户名和密码来证明自己的身份,但网络钓鱼攻击可以通过欺骗用户来窃取这两项信息。
为应对网络钓鱼攻击,安全团队已着手部署多因素身份验证 (MFA) 工具,以新增一个附加的安全层。用户需要输入其用户名、密码和部分其他值。例如,用户可能在其设备上运行一个生成随机数字的应用程序,也可能使用其电话号码注册以通过短信接收代码。虽然这些 MFA 选项确实助力用户提高了安全性,但用户仍易受到网络钓鱼攻击。网络钓鱼网站循循善诱,促使用户输入 MFA 代码,或者攻击者通过 SIM 卡交换攻击来窃取用户的电话号码。
硬件安全密钥可为企业提供一个防御网络钓鱼的 MFA 选项。这些密钥采用 WebAuthn 标准来向身份验证服务提供证书,从而在以加密方式保障安全性的交换中验证密钥,这是网络钓鱼网站无法获得、因此也无法骗取的信息。
用户通过其标识提供程序注册一个或多个密钥,除了让用户出示其用户名和密码外,提供程序还可能通过一个 MFA 选项提示用户输入硬件密钥。安全团队中的每一位成员在登录时点击密钥(而不是在应用程序中摸索代码),即可享受更顺畅的体验。此外,安全团队的成员如知晓其服务能够防御网络钓鱼攻击,必定能够安枕无忧。
\n虽然目前大多数标识提供程序允许用户注册硬件密钥作为 MFA 选项,但管理员仍然没有控制权来要求使用硬件密钥。个人用户如果不能出示安全密钥本身,则可以退回到一个不太安全的选项,如基于应用程序的代码。
当 Cloudflare 首次部署安全密钥时,我们就遇到了这个问题。如果用户可以退回到一个不太安全且更容易遭到网络钓鱼攻击的选项,如基于应用程序的代码,那么攻击者也同样可以。我们携手 10,000 多个企业,在内部使用 Cloudflare 的 Zero Trust 产品,以部分确保用户连接到其需要的资源和工具的安全。
当任何用户需要访问内部应用程序或服务时,Cloudflare 的网络会评估每次请求或连接的多个信号,例如标识、设备状态和国家/地区。管理员也可以构建仅适用于某些目的地的精细规则。具有客户数据读取能力的内部管理员工具可能要求健康状况良好的公司设备连接自某个特定的国家/地区,并归特定标识提供程序组中的某个用户所有。此外,可能只需要标识即可通过共享一个新的营销启动页面来获取反馈。如果我们可以在用户的身份验证过程中出示安全密钥,而不是其他不太安全的 MFA 选项,那么我们也可以强制执行该信号。
几年前,标识提供程序、硬件供应商和安全公司合作开发了一项新的标准 — 身份验证方法参考标准 (AMR),目的正是为了分享此类数据。根据 AMR,标识提供程序可以分享关于登录尝试的多项详情,包括正在使用的 MFA 选项的类型。该公告发布后不久,我们在 Cloudflare 的 Zero Trust 套件中推出了规则构建功能,以寻找和执行该信号。如今,任何规模的团队都可以构建基于资源的规则,从而确保团队成员始终使用其硬件密钥。
\n保证您实际控制的事物的安全性,也是导致部署硬件密钥增加了一层复杂性的原因—您需要找到一种方法,将这种物理密钥批量交由用户保管,使您团队的每一位成员都可以注册安全密钥。
在所有情况下,必须先购买硬件安全密钥才能实施这种部署。与基于应用程序的代码(可能是免费的)相比,安全密钥会产生实际成本。对于一些企业而言,这种成本让人望而却步,继而导致其安全性较低,但要注意的是,并非所有的 MFA 都具备同等效力。
对于其他团队而言,特别是目前部分或完全实施远程办公的企业,向永远不会踏入实体办公室的终端用户提供这些密钥,对 IT 部门而言是一项莫大的挑战。Cloudflare 首次部署硬件密钥是在公司级务虚会上完成的。许多企业不再有这种机会在单一场所乃至全球办公室内以物理方式发放密钥。
\nCloudflare 生日周始终是为了消除阻碍用户和团队更安全或更快速地访问互联网的壁垒和障碍而举办的。在实现该目标的过程中,我们与 Yubico 开展合作,继续消除采用硬件密钥安全模式的摩擦。
这款产品向所有 Cloudflare 客户开放。Cloudflare 客户可直接在 Cloudflare Dashboard 中针对 Yubico 安全密钥申领这款产品。
Yubico 将以“适合互联网”的价格提供安全密钥 — 每个密钥低至 10 美元。Yubico 将直接向客户发放密钥。
Cloudflare 和 Yubico 的开发人员文档和支持部门都将指导客户设置密钥并将其与他们的标识提供程序和 Cloudflare 的 Zero Trust 服务相整合。
您可以导航到仪表板,按照横幅通知中列出的流程申请您自己的硬件密钥。届时,Yubico 将以电子邮件形式将您申请的硬件密钥直接发送至您在 Cloudflare 帐户中提供的管理员电子邮箱。希望批量部署 YubiKey 的大型企业,可以探索 Yubico 的 YubiEnterprise 订阅并在三年期订阅中的第一年享受 50% 的折扣。
已经拥有硬件安全密钥?如果您拥有物理硬件密钥,则可以开始在 Cloudflare Access 中构建规则,从而通过将它们注册到支持 AMR 的标识提供程序(如 Okta 或 Azure AD)中来强制使用它们。
最后,如果您有意自行一同部署 Yubikeys 与我们的 Zero Trust 产品,请查看我们的安全总监 Evan Johnson 的这篇博文,其中回顾了 Cloudflare 的经验以及我们根据经验教训提出的建议。
"],"published_at":[0,"2022-09-29T14:01:00.000+01:00"],"updated_at":[0,"2024-10-09T23:20:33.720Z"],"feature_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7q17lZyvkc4to7tOGHJMM7/d9fed980685bc4d0714941f123c939fc/making-phishing-defense-seamless-cloudflare-yubico.png"],"tags":[1,[[0,{"id":[0,"1Cv5JjXzKWKEA10JdYbXu1"],"name":[0,"Birthday Week"],"slug":[0,"birthday-week"]}],[0,{"id":[0,"J61Eszqn98amrYHq4IhTx"],"name":[0,"Zero Trust"],"slug":[0,"zero-trust"]}],[0,{"id":[0,"4Z2oveL0P0AeqGa5lL4Vo1"],"name":[0,"Cloudflare One"],"slug":[0,"cloudflare-one"]}],[0,{"id":[0,"6Mp7ouACN2rT3YjL1xaXJx"],"name":[0,"安全"],"slug":[0,"security"]}],[0,{"id":[0,"6QktrXeEFcl4e2dZUTZVGl"],"name":[0,"产品新闻"],"slug":[0,"product-news"]}],[0,{"id":[0,"3QNaVNNpUXrfZYUGDJkXwA"],"name":[0,"Cloudflare Zero Trust"],"slug":[0,"cloudflare-zero-trust"]}]]],"relatedTags":[0],"authors":[1,[[0,{"name":[0,"David Harnett"],"slug":[0,"davidharnett"],"bio":[0,"Joined Cloudflare with the acquisition of S2 Systems and now Director of Product Management for Cloudflare for Teams"],"profile_image":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/39zMXAXt2G4ZLhOjPr8vOM/5f46e5a51279e0ff12771a92fed668df/davidharnett.PNG"],"location":[0,"Seattle"],"website":[0,"https://www.linkedin.com/in/david-harnett/"],"twitter":[0,"@dfh603"],"facebook":[0,"david.harnett.16"]}]]],"meta_description":[0,"Announcing a new collaboration with Yubico, to remove any barriers for organizations of any size to deploying hardware security keys."],"primary_author":[0,{}],"localeList":[0,{"name":[0,"The (hardware) key to making phishing defense seamless with Cloudflare Zero Trust and Yubico Config"],"enUS":[0,"English for Locale"],"zhCN":[0,"Translated for Locale"],"zhHansCN":[0,"No Page for Locale"],"zhTW":[0,"No Page for Locale"],"frFR":[0,"Translated for Locale"],"deDE":[0,"Translated for Locale"],"itIT":[0,"No Page for Locale"],"jaJP":[0,"Translated for Locale"],"koKR":[0,"No Page for Locale"],"ptBR":[0,"No Page for Locale"],"esLA":[0,"No Page for Locale"],"esES":[0,"Translated for Locale"],"enAU":[0,"No Page for Locale"],"enCA":[0,"No Page for Locale"],"enIN":[0,"No Page for Locale"],"enGB":[0,"No Page for Locale"],"idID":[0,"No Page for Locale"],"ruRU":[0,"No Page for Locale"],"svSE":[0,"No Page for Locale"],"viVN":[0,"No Page for Locale"],"plPL":[0,"No Page for Locale"],"arAR":[0,"No Page for Locale"],"nlNL":[0,"No Page for Locale"],"thTH":[0,"No Page for Locale"],"trTR":[0,"No Page for Locale"],"heIL":[0,"No Page for Locale"],"lvLV":[0,"No Page for Locale"],"etEE":[0,"No Page for Locale"],"ltLT":[0,"No Page for Locale"]}],"url":[0,"https://blog.cloudflare.com/making-phishing-defense-seamless-cloudflare-yubico"],"metadata":[0,{"title":[0,"借助 Cloudflare Zero Trust 和 Yubico 实现对网络钓鱼的无缝防御的关键(硬件密钥)"],"description":[0,"Announcing a new collaboration with Yubico, to remove any barriers for organizations of any size to deploying hardware security keys."],"imgPreview":[0,"https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5L8jccFgf5CU1n8cdnSHIK/c2025c708864c070dbbb7ed5deb0bc01/making-phishing-defense-seamless-cloudflare-yubico-flSaGd.png"]}]}],"locale":[0,"zh-cn"],"translations":[0,{"posts.by":[0,"作者"],"footer.gdpr":[0,"GDPR"],"lang_blurb1":[0,"这篇博文也有 {lang1} 版本。"],"lang_blurb2":[0,"这篇博文也有 {lang1} 和{lang2}版本。"],"lang_blurb3":[0,"这篇博文也有 {lang1}、{lang2} 和{lang3}版本。"],"footer.press":[0,"新闻"],"header.title":[0,"Cloudflare 博客"],"search.clear":[0,"清除"],"search.filter":[0,"过滤"],"search.source":[0,"来源"],"footer.careers":[0,"招聘"],"footer.company":[0,"公司"],"footer.support":[0,"支持"],"footer.the_net":[0,"theNet"],"search.filters":[0,"过滤器"],"footer.our_team":[0,"我们的团队"],"footer.webinars":[0,"网络研讨会"],"page.more_posts":[0,"更多帖子"],"posts.time_read":[0,"{time} 分钟阅读时间"],"search.language":[0,"语言"],"footer.community":[0,"社区"],"footer.resources":[0,"资源"],"footer.solutions":[0,"解决方案"],"footer.trademark":[0,"商标"],"header.subscribe":[0,"订阅"],"footer.compliance":[0,"合规性"],"footer.free_plans":[0,"Free 计划"],"footer.impact_ESG":[0,"影响/ESG"],"posts.follow_on_X":[0,"在 X 上关注"],"footer.help_center":[0,"帮助中心"],"footer.network_map":[0,"网络地图"],"header.please_wait":[0,"请稍候"],"page.related_posts":[0,"相关帖子"],"search.result_stat":[0,"针对 {search_keyword} 的第 {search_range} 个搜索结果(共 {search_total} 个结果)"],"footer.case_studies":[0,"案例研究"],"footer.connect_2024":[0,"Connect 2024"],"footer.terms_of_use":[0,"服务条款"],"footer.white_papers":[0,"白皮书"],"footer.cloudflare_tv":[0,"Cloudflare TV"],"footer.community_hub":[0,"社区中心"],"footer.compare_plans":[0,"比较各项计划"],"footer.contact_sales":[0,"联系销售"],"header.contact_sales":[0,"联系销售团队"],"header.email_address":[0,"电子邮件地址"],"page.error.not_found":[0,"未找到页面"],"footer.developer_docs":[0,"开发人员文档"],"footer.privacy_policy":[0,"隐私政策"],"footer.request_a_demo":[0,"请求演示"],"page.continue_reading":[0,"继续阅读"],"footer.analysts_report":[0,"分析报告"],"footer.for_enterprises":[0,"企业级服务"],"footer.getting_started":[0,"开始使用"],"footer.learning_center":[0,"学习中心"],"footer.project_galileo":[0,"Project Galileo"],"pagination.newer_posts":[0,"较新的帖子"],"pagination.older_posts":[0,"较旧的帖子"],"posts.social_buttons.x":[0,"在 X 上讨论"],"search.icon_aria_label":[0,"搜索"],"search.source_location":[0,"来源/位置"],"footer.about_cloudflare":[0,"关于 Cloudflare"],"footer.athenian_project":[0,"Athenian Project"],"footer.become_a_partner":[0,"成为合作伙伴"],"footer.cloudflare_radar":[0,"Cloudflare Radar"],"footer.network_services":[0,"网络服务"],"footer.trust_and_safety":[0,"信任与安全"],"header.get_started_free":[0,"免费开始使用"],"page.search.placeholder":[0,"搜索 Cloudflare"],"footer.cloudflare_status":[0,"Cloudflare 状态"],"footer.cookie_preference":[0,"Cookie 首选项"],"header.valid_email_error":[0,"必须是有效的电子邮件地址。"],"search.result_stat_empty":[0,"显示第 {search_range} 个结果(共 {search_total} 个结果)"],"footer.connectivity_cloud":[0,"全球连通云"],"footer.developer_services":[0,"开发人员服务"],"footer.investor_relations":[0,"投资者关系"],"page.not_found.error_code":[0,"错误代码:404"],"search.autocomplete_title":[0,"请输入查询内容。按回车键发送"],"footer.logos_and_press_kit":[0,"标识与媒体资料包"],"footer.application_services":[0,"应用程序服务"],"footer.get_a_recommendation":[0,"获得推荐"],"posts.social_buttons.reddit":[0,"在 Reddit 上讨论"],"footer.sse_and_sase_services":[0,"SSE 和 SASE 服务"],"page.not_found.outdated_link":[0,"您可能使用了过期的链接,或者输入了错误的地址。"],"footer.report_security_issues":[0,"报告安全问题"],"page.error.error_message_page":[0,"抱歉,我们找不到您要打开的页面。"],"header.subscribe_notifications":[0,"订阅以接收新文章的通知:"],"footer.cloudflare_for_campaigns":[0,"Cloudflare for Campaigns"],"header.subscription_confimation":[0,"订阅已确认。感谢订阅!"],"posts.social_buttons.hackernews":[0,"在 Hacker News 上讨论"],"footer.diversity_equity_inclusion":[0,"多元、公平与包容"],"footer.critical_infrastructure_defense_project":[0,"关键基础设施防护项目"]}]}" ssr="" client="load" opts="{"name":"PostCard","value":true}" await-children="">2022-09-29
宣布与 Yubico 开展新的合作,为任何规模的企业部署硬件密钥消除障碍...
2022-06-23
隆重推出 Cloudflare One 合作伙伴计划。该计划建立在我们的 Zero Trust、网络即服务和云电子邮件安全产品的基础之上。该计划帮助渠道合作伙伴兑现 Zero Trust 的承诺,同时以切实的方式实现这一重要架构的货币化...